Validate a qualified electronic signature against eIDAS requirements using the EU's DSS (Digital Signature Service) library

domain: ec.europa.eu · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Use the DSS open-source library (or its public demo web app) to validate AdES-conformant signature formats - PAdES, XAdES, CAdES, and ASiC containers - per the ETSI EN 319 102-1 validation procedures it implements.
  2. Supply DSS the signed document (plus a detached signature file if applicable) and, optionally, a signature validation policy constraints file defining which checks (certificate chain, revocation, qualification) must pass.
  3. Run validation and read the resulting indication: TOTAL-PASSED means all cryptographic checks and every check required by the validation policy succeeded; other indications (e.g., TOTAL-FAILED, INDETERMINATE) mean the signature does not fully pass.
  4. To determine specific Qualified Electronic Signature (QES) status, use DSS's QES validation algorithm (available since DSS 5.5), which layers the CEF eSignature Building Block's interpretation of eIDAS/ETSI qualified-certificate rules on top of base AdES validation, checking the signing certificate's qualified status against EU Member State Trusted List data.
  5. For a one-off check without self-hosting DSS, use the European Commission's free public eSignature Validator / DSS demo web app, which runs the same underlying library.

Known gotchas

Related routes

Verify the legal validity tier of an e-signature under ESIGN, UETA, and eIDAS frameworks
contracts-general · 6 steps · unrated
Implement a Qualified Electronic Signature (QES) remote signing flow using a QTSP's signing API under eIDAS
ec.europa.eu · 6 steps · unrated
Configure an eIDAS-compliant electronic identity verification flow using an EU member state eID via the CEF eIDAS node connector
ec.europa.eu · 5 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans